Skip to content
CERT-In flags high-severity vulnerabilities in Apple devices, urges users to update software

CERT-In flags high-severity vulnerabilities in Apple devices, urges users to update software

Storyboard18 March 30, 2026

India’s cybersecurity agency, the Indian Computer Emergency Response Team (CERT-In), has issued a high-severity alert for Apple users, warning of multiple vulnerabilities across devices including iPhone, iPad, Mac and Apple Watch. The advisory, released on March 26, 2026, flagged risks that could allow attackers to access sensitive data or take control of affected systems.

‘High severity’ flaws flagged

CERT-In, which functions under the Ministry of Electronics and Information Technology, classified the vulnerabilities as “high severity.” It said multiple flaws exist across Apple’s operating systems and software that attackers could exploit to execute arbitrary code, gain elevated privileges, and bypass security restrictions. The agency also warned of risks such as information disclosure and denial-of-service (DoS) attacks, affecting both individual users and organisations.

Multiple weaknesses across the ecosystem

According to CERT-In, the vulnerabilities arise from issues across different components of Apple’s software ecosystem, including system elements and security mechanisms. These flaws may allow attackers to manipulate system behaviour or bypass built-in protections. The advisory noted that the presence of multiple CVEs indicates a wider attack surface, where vulnerabilities across systems and applications could be combined. This may lead to remote code execution, privilege escalation, and exposure of sensitive information.

Devices, software versions impacted

The alert applies to a wide range of Apple devices, particularly those running older software versions. These include iOS and iPadOS versions prior to 26.4 and 18.7.7, macOS Tahoe versions prior to 26.4, macOS Sequoia versions prior to 15.7.5, macOS Sonoma versions prior to 14.8.5, Safari versions prior to 26.4, watchOS, tvOS and visionOS versions prior to 26.4, and Apple Xcode versions prior to 26.4. The affected ecosystem spans iPhone, iPad, Mac, Apple Watch and Apple Vision Pro devices.

Users advised to update immediately

CERT-In has advised users to take immediate steps to reduce risk, emphasising that updating devices remains the primary safeguard. Users have been asked to install the latest software updates and official security patches, avoid clicking on suspicious links or downloading unknown files, use trusted app sources, and regularly back up important data. The agency warned that devices running outdated software remain more vulnerable to risks such as data theft, malware spread, system crashes, and unauthorised access.